STATUS: ACTIVE
Definition · XWorm Basics

What Is XWorm? Complete Malware Analysis

An authoritative definition and technical overview of XWorm, the modular .NET Windows Remote Access Trojan first observed in 2022.

AUTHOR: Threat Intelligence Research TeamUPDATED: 2026-10-04VERIFIED: 2026-10-04VERSION: All

XWorm is a modular Remote Access Trojan (RAT) primarily targeting Microsoft Windows. It has been publicly observed since 2022 and is commonly implemented using Microsoft's .NET ecosystem. XWorm allows unauthorized operators to remotely control compromised systems and can support functionality including system reconnaissance, file management, remote command execution, keylogging, screenshots, webcam access, microphone surveillance, browser credential theft, cookie theft, clipboard monitoring, cryptocurrency-related theft, additional payload delivery, modular plugin execution, persistence, and disruptive functions.

Microsoft currently describes XWorm as a RAT distributed through a Malware-as-a-Service (MaaS) ecosystem and associated with phishing and ClickFix campaigns.

Important clarification
Despite the word "Worm" in its name, XWorm is primarily tracked by security vendors as a Remote Access Trojan. Do not assume that every XWorm infection automatically involves autonomous network-worm propagation.

Key Facts

  • TypeRemote Access Trojan
  • PlatformMicrosoft Windows
  • Runtime.NET (managed)
  • First observed2022
  • Original developer aliasXCoder / EvilCoder
  • Latest verified version7.4
  • Distribution modelMaaS / cracked / modified
  • Current statusActive in 2026

Origin — 2022

Public research identifies XWorm activity dating to 2022. Cyble documented the "EvilCoder" malware project on August 19, 2022 and analyzed XWorm as part of a collection of malicious tooling advertised online. Security research has associated development and marketing with the aliases XCoder and EvilCoder. Palo Alto Networks also identifies XWorm as a .NET Windows RAT sold under aliases including XCoder or EvilCoder.

Terminology note
These are developer aliases / online handles / malware-development identities — not confirmed real-world persons. We do not claim these aliases identify a confirmed individual.

Capability Overview

XWorm supports a broad surveillance and control surface. Documented capability categories include surveillance (keylogging, screenshots, webcam, microphone, clipboard), credential and information theft (browser credentials, cookies, MetaMask, Telegram sessions), system control (remote shell, file management, payload execution), reconnaissance, financial/cryptocurrency abuse (clipboard address replacement), and impact functions (file encryption, DDoS in some plugins).

Because XWorm is modular, capability profiles differ between operators and builds. See the Capability Matrix and Plugin Architecture for details.

Defensive Classification

PHISHING / SOCIAL ENG.
↓
LOADER / SCRIPT
↓
MEMORY STAGE
↓
PERSISTENCE
↓
XWORM CORE
↓
C2 COMMUNICATION
↓
DATA EXFIL

XWorm sits at the end of a delivery chain. The malware itself should be distinguished from the loaders, exploits, and social-engineering used to install it. An exploit used by a loader does not automatically become an intrinsic XWorm capability.

References

  1. [1]Cyble, EvilCoder Project Selling Multiple Dangerous Tools Online, 2022-08-19
  2. [2]Trellix, Old Loader, New Threat: Exploring XWorm RAT's Distribution and Tactics, 2023-07-31
  3. [3]Palo Alto Networks, XWorm persistence and XCoder/EvilCoder attribution research, 2023
  4. [4]Proofpoint, Cloudflare Tunnel campaigns delivering XWorm and AsyncRAT, 2024
  5. [5]Microsoft Security Intelligence, XWorm malware encyclopedia entries, 2025-2026
  6. [6]Trellix, XWorm's Evolving Infection Chain: From Predictable to Deceptive, 2025-09-03
XWorm Full Tech Access — 0.10 BTC — Access Granted, Network Mapped
@echophant